incident

OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident

OpenAI disclosed that a GitHub Actions workflow used for signing its macOS apps unintentionally downloaded a malicious version of the Axios npm package as part of a supply chain attack linked to North Korean hackers, but affirmed no user data or internal systems were compromised. In response, OpenAI revoked and rotated the affected signing certificate, blocking older app versions and coordinating with Apple to prevent further notarizations with the compromised certificate, highlighting the growing threat and complexity of software supply chain attacks.

https://thehackernews.com/2026/04/openai-revokes-macos-app-certificate.html

GTA 6 Developer Rockstar Reportedly Hacked, Data Being Ransomed

Hacker group ShinyHunters claims to have breached Rockstar Games' secured cloud servers via a security flaw in a third-party service, Anodot, demanding a ransom by April 14 or threatening to leak corporate data. Rockstar confirmed a data breach occurred but stated that only a limited amount of non-material company information was accessed, with no impact on their organization or players.

https://kotaku.com/rockstar-games-reportedly-hacked-massive-data-leak-ransom-gta-6-shinyhunters-2000686858

Over 20,000 Crypto Fraud Victims Identified in International Crackdown

An international law enforcement effort called Operation Atlantic, led by the UK's National Crime Agency (NCA) and involving agencies from Canada, the UK, and the US, has identified over 20,000 victims of cryptocurrency fraud and frozen more than $12 million in criminal proceeds. This joint operation disrupted multiple fraud networks globally, highlighting the effectiveness of public-private partnerships in combating crypto scams and supporting victims.

https://www.bleepingcomputer.com/news/security/police-identifies-20-000-victims-in-international-crypto-fraud-crackdown/

European Commission Cloud Breach: a Supply-Chain Compromise

In March 2026, the European Commission's AWS cloud account hosting public websites was compromised through the Trivy supply-chain attack linked to the threat actor TeamPCP, resulting in the exfiltration of approximately 91.7 GB of compressed data, including personal information and email content from multiple Union entities. The compromise, detected by the European Commission’s Cybersecurity Operations Centre and CERT-EU, led to a data leak published by the extortion group ShinyHunters, prompting immediate revocation of affected credentials, notifications to data protection authorities, and ongoing investigations into the incident's impact.

https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain

Anthropic Accidentally Exposes Claude Code Source Code

Anthropic accidentally exposed the entire source code of its AI coding tool, Claude Code, through an npm package that included a map file referring to unobfuscated TypeScript files in a publicly accessible archive. The leak, caused by human error in the release packaging process, allowed security researchers and others to download over 512,000 lines of code, although Anthropic confirmed no customer data was compromised and is implementing measures to prevent future incidents.

https://www.theregister.com/2026/03/31/anthropic_claude_code_source_code/

Axios Compromised on npm – Malicious Versions Drop Remote Access Trojan

The popular JavaScript HTTP client library, axios, was compromised on npm with malicious versions 1.14.1 and 0.30.4, injecting a hidden dependency, [email protected], which executes a postinstall script that drops a cross-platform remote access trojan (RAT). This sophisticated supply chain attack hijacked a maintainer's npm account to publish poisoned releases that contact a command-and-control server, deploy platform-specific payloads, self-delete to avoid detection, and were detected by StepSecurity’s tools, with remediation guidance provided.

https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan

Stryker Rules Out Ransomware, Confirms Threat Actor Used Non-Propagating Malicious File

Medical technology company Stryker confirmed that its recent cybersecurity incident did not involve ransomware but rather a non-propagating malicious file used by threat actors to conceal activity within its systems. The company, working with Palo Alto Networks' Unit 42 and government agencies, stated the breach is contained with no evidence of impact on customers, suppliers, or partners, and prioritized restoring operations while continuing investigations.

https://industrialcyber.co/medical/stryker-rules-out-ransomware-confirms-threat-actor-used-non-propagating-malicious-file/

Pumping the Brakes on Anthropic’s Leaked Cybersecurity AI

A leaked draft blog post revealed Anthropic’s new AI model, Capybara, which reportedly outperforms its previous flagship in cybersecurity tasks, but raised concerns about AI security and data protection. The leak, attributed to human error, sparked a sharp decline in cybersecurity stocks and underscored the growing risks as AI advances faster than defenses, prompting calls for stronger AI governance.

https://www.paymentsjournal.com/pumping-the-brakes-on-anthropics-leaked-cybersecurity-ai/

Stryker Says Malware Was Involved in Recent Cyberattack as Production Lines Reopen

Medical device company Stryker is restarting production lines two weeks after a cyberattack by alleged Iranian hackers wiped data from over 200,000 devices, disrupting hospital operations in Maryland. The company confirmed the use of malware to conceal attacker activities but stated the cyberattack targeted internal systems, with no evidence of compromise to customer or partner devices, and restoration efforts are underway.

https://therecord.media/stryker-cyberattack-malware-iran

Rogue AI Agent Triggers Emergency at Meta

A rogue AI agent at Meta caused a security incident last week by posting inaccurate information on an internal forum, which led to unauthorized access to sensitive company and user data for nearly two hours. Meta classified the event as a high-severity “SEV1” incident but stated no user data was mishandled, attributing the issue to human error rather than technical changes by the AI itself. This incident highlights ongoing safety challenges with AI systems, similar to prior AI-related outages at companies like Amazon.

https://futurism.com/artificial-intelligence/rogue-ai-agent-triggers-emergency-at-meta

The Company Paid to Protect Your Identity Just Got Hacked

Aura, a major U.S. identity protection company serving over a million customers, suffered a data breach after an employee fell victim to a phone phishing attack, allowing hackers to access and steal around 900,000 records within an hour. The stolen data, primarily names and contact details, was released online by the hacking group ShinyHunters after Aura declined to pay a ransom, highlighting the risks of social engineering even for firms specializing in security.

https://gizmodo.com/the-company-paid-to-protect-your-identity-just-got-hacked-2000735410

Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish

Security firm Outpost24 recently thwarted a sophisticated phishing attack targeting a C-level executive that used a complex seven-stage redirect chain involving trusted brands like Cisco and JP Morgan. The attackers employed legitimate services and expired domains to bypass email security, ultimately leading to a Microsoft Office credential phishing page, highlighting the increasing use of layered, evasive phishing tactics even against cybersecurity providers. This incident underscores the need for layered defenses and zero-trust principles, as compromising vendor credentials can grant attackers trusted access to multiple organizations.

https://www.darkreading.com/threat-intelligence/hackers-target-cybersecurity-firm-outpost24-phish

Stryker Attack Wiped Tens of Thousands of Devices, No Malware Needed

Last week's cyberattack on medical technology company Stryker involved the remote wiping of nearly 80,000 employee devices by exploiting Microsoft Intune administrative privileges, but no malware was deployed and no medical devices were affected. The incident, attributed to the Handala group linked to Iran, disrupted internal corporate systems and electronic ordering, with restoration efforts ongoing to resume normal operations.

https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/

The Who, What, and Why of the Attack That Has Shut Down Stryker’s Windows Network

Stryker, a major multinational medical device supplier, confirmed a cyberattack that disrupted much of its Microsoft network, with a hacking group called Handala Hack—linked to the Iranian government—claiming responsibility. The attack, suspected to have involved remote wiping of devices via Microsoft’s InTune tool rather than typical malware, followed recent US and Israeli airstrikes on Iran, suggesting retaliation through cyber means. Despite the disruption, Stryker’s critical medical devices remain operational, though the company has not yet provided a timeline for full recovery.

https://arstechnica.com/security/2026/03/whats-known-about-wiper-attack-on-stryker-a-major-supplier-of-lifesaving-devices/

Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

Iran-linked hacktivist group Handala claims responsibility for a data-wiping attack on Stryker, a major medical technology company. The attack forced the shutdown of Stryker's global operations, impacting over 200,000 devices and disrupting supply chains for healthcare providers. The group stated the action was retaliation for a missile strike in Iran that killed many civilians. The incident has raised concerns about cybersecurity in the healthcare sector, as hospitals consider disconnecting from Stryker's services amid the attack.

https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/

Scroll to Top